If you're reading this you've landed on a URL that doesn't feel right and you want a verdict before you type a card number, sign a wallet transaction, or send a "verification fee". Good instinct — about 38% of every verified threat on the GACS blacklist is a phishing or imposter website, and the median victim ignored at least three of the signals below.
This guide walks you through the exact checks a fraud analyst runs, in the order they run them, plus what to do when a check is ambiguous. Total time: under 5 minutes by hand, or 4 seconds with the Safe Scanner.
The 90-second triage (do this first)
Before you read anything else, run these three checks. If any one of them fails, you don't need to read the rest of the guide — close the tab.
- Paste the URL into [Safe Scanner](/safe-scanner). It cross-checks 250k+ blacklisted entities, WHOIS age, SSL fingerprint, content patterns, and known scam-front templates in one call. A red verdict here is the end of the conversation.
- Read the URL out loud.
amaz0n-support.com,metamask-recovery.app,binance-claim.io— homoglyphs, hyphenated brand names, and "support / claim / recovery / update" subdomains are the single most common scam pattern of 2026. - Check who the site asks you to pay. If the only deposit option is USDT-TRC20, raw BTC, gift cards, or a wire to a personal name, the site is a scam regardless of how polished it looks.
If all three pass, keep going — the next checks separate "probably legitimate" from "definitely legitimate".
Check 1 — domain age (WHOIS)
The single highest-signal metric. A real business has a domain older than its first customer; a scam operation spins one up the week before the campaign.
- Tool:
whois example.comfrom a terminal, or any free WHOIS lookup (who.is, ICANN Lookup). - What to read: the Creation Date field. Ignore "Updated Date" — that just means someone renewed.
- The bands:
- - Under 30 days → assume scam until proven otherwise. 78% of phishing domains in our 2026 sample were under 60 days old at first observation.
- - 30 days to 6 months → high risk. Could be a new legitimate brand; require every other signal to be perfect.
- - 6 to 24 months → moderate trust. Combine with the other checks below.
- - 2+ years with consistent WHOIS → strong trust signal.
Gotcha: scammers buy aged "drop-caught" domains specifically to defeat this check. Cross-reference with the Wayback Machine (web.archive.org) — if a 5-year-old domain has no archived snapshots until last month, it was sitting empty and is now a re-purposed shell.
Check 2 — SSL certificate detail
Every site has HTTPS in 2026 because Let's Encrypt is free. The padlock icon proves nothing. What you need is what kind of certificate and who issued it to whom.
- Click the padlock → Certificate → Details.
- Issuer: Let's Encrypt, ZeroSSL, Cloudflare — fine on their own, but offer zero identity verification.
- Subject: This is the part that matters. A legitimate broker, bank, or exchange has either an Organization Validation (OV) or Extended Validation (EV) certificate listing the company's legal name. A scam site has only the domain name in the Subject — no organization, no jurisdiction.
- Validity period: A 90-day cert from Let's Encrypt issued yesterday on a 14-day-old domain is the textbook phishing profile.
For any site asking for money, the absence of an OV or EV certificate alone is enough to walk away.
Check 3 — the UI patterns scam sites can't stop using
After triaging hundreds of fake-broker and phishing sites, the same UI tells repeat. None of these is conclusive on its own, but three or more together is a near-certain scam:
- Countdown timer on the deposit page ("offer ends in 04:59"). Real exchanges don't pressure deposits.
- Live "withdrawal" ticker showing fake usernames cashing out. Always faked; often the same names cycle every refresh.
- Stock photos of "the team" that reverse-image-search to TheStockMarket.com, Unsplash, or "100 ceo headshots" packs. Try a Google reverse image search on every face on the About page.
- Broken English mixed with corporate boilerplate — copy-pasted T&Cs from a real exchange next to home-page copy a native speaker wouldn't write.
- A live-chat widget that responds instantly with a "manager" offering a bonus, a higher tier, or "VIP access" to make you deposit more.
- Customer-support hours listed as "24/7" but no phone number, no physical address, no registration number.
- Withdrawal page is hidden, paywalled, or requires "level 2 verification" that requires another deposit. This is the scam confession — the moment you see it, the platform is fake.
Check 4 — the regulator and registry trail
If the site claims to be a broker, bank, exchange, or any kind of licensed financial business, the licence is verifiable in 30 seconds. There is no excuse for not checking it.
- US: SEC EDGAR, FINRA BrokerCheck, NFA BASIC, CFTC RED list, FTC scam alerts.
- UK: FCA Register — and the FCA's "unauthorised firms" warning list, which catches clones using a real firm's licence number.
- EU / Germany: BaFin company database.
- Australia: ASIC professional registers.
- Singapore: MAS Financial Institutions Directory.
- Canada: CSA National Registration Search.
The clone trick: scam brokers often copy a legitimate firm's name, address, and licence number, then publish a slightly-different website. Always cross-check the website URL on the regulator's record — if the regulator lists legitfirm.com and the site you're on is legitfirm-pro.com, the site is a clone.
For non-financial websites (shops, services), the equivalents are: country-specific company registers (Companies House in the UK, OpenCorporates globally), a verifiable physical address on Google Street View, and a registered VAT number that validates on the official VIES (EU) or HMRC (UK) lookup.
Check 5 — payment rails
How a site asks you to pay is the loudest single signal. Legitimate businesses accept reversible, regulated rails because their customers demand it. Scams insist on irreversible ones.
| Payment rail | Verdict | | --- | --- | | Major credit cards (Visa, Mastercard, Amex) with 3D Secure | Trust signal — chargeable, regulated | | Apple Pay / Google Pay | Trust signal — buyer protection inherited from card network | | PayPal Goods & Services | Moderate trust — eligible for buyer protection | | Stripe / Adyen / Braintree checkout | Trust signal — KYC'd merchant onboarding | | Bank wire to a registered company name | Moderate — verify the receiving company name matches | | Bank wire to a personal name | Scam confession. Walk away. | | USDT-TRC20, raw BTC, deposit-only crypto address | High risk — irreversible, favorite scam laundering rail | | "Pay our agent in gift cards" | Scam confession. Always. | | "Pay via Western Union / MoneyGram" | Scam confession. Always. |
A site that *only* offers irreversible rails has chosen those rails deliberately. There is no neutral reading.
Check 6 — reputation outside the site itself
Never trust testimonials hosted on the site you're verifying. The site controls them. Check what users say where the site can't moderate:
- Trustpilot, Sitejabber, Reddit — search "[brand name] withdrawal" and "[brand name] scam". A pattern of "couldn't withdraw" complaints from the last 30 days is the loudest possible signal.
- ScamAdviser, URLVoid, GACS [scam alerts](/scam-alerts) — aggregated signal across multiple blocklists.
- Reverse-search the company name + "lawsuit" on Google. Legitimate firms sometimes have lawsuits; scams almost always do, often under previous brand names.
- LinkedIn — does the listed CEO exist? Do they have prior roles in the stated industry? A profile created last month with no connections is not a CEO.
If you see five or more 1-star withdrawal complaints in the last 30 days, the platform is dead — your money will not come back.
Check 7 — technical infrastructure tells
For a deeper look — useful when the site is polished enough to pass the basic checks — run:
- `dig` or `nslookup` on the domain. Scam sites often share IP space (or even the same /24) with dozens of other scam sites. Cross-reference with URLhaus.
- Page source view (Ctrl+U) for placeholder strings the operator forgot to replace:
{{COMPANY_NAME}},Lorem ipsum,[CHANGE THIS BEFORE LAUNCH]. More common than you'd think. - Built-with detection (BuiltWith, Wappalyzer). A "regulated US broker" running on a free Wix theme is not a regulated US broker.
- Email lookup. A real company's support email is on the company's own domain.
support@gmail.comorfinance@protonmail.comis a freelancer, not a financial institution.
The fastest path: run it through Safe Scanner
Every check above is automated in the free GACS Safe Scanner. It runs:
- Blacklist lookup against 250k+ verified scam entities and the live URLhaus phishing feed.
- WHOIS age with the same Creation Date logic above, plus drop-catch detection via Wayback cross-reference.
- SSL certificate inspection — issuer, subject, OV/EV detection.
- Content-pattern matching for the UI tells in Check 3, including stock-photo reverse search and copy-paste boilerplate detection.
- Payment-rail extraction — detects USDT-TRC20 deposit-only patterns, missing card processors, and gift-card asks.
- Reputation aggregation — pulls recent Trustpilot, Reddit, and GACS community reports.
You get one verdict in 4 seconds: green (safe), yellow (suspicious — see report), or red (confirmed scam — do not pay).
What to do if the site fails
- Do not pay anything. Not a "verification fee", not a "small test transaction", not a "tax". The fee *is* the scam.
- Screenshot the site — full page, including the URL bar. Use a tool like GoFullPage, not a phone photo.
- Report it via your country's fraud channel. We've published step-by-step report guides for the US, UK, Canada, Australia, India, Singapore, Philippines, Nigeria, South Africa, and the UAE.
- Submit it to the GACS blacklist via /report-a-scam so the next person who lands on the URL gets a red verdict from the scanner.
- If you already paid, open the Panic Guide — the first 24 hours determine almost everything about recovery.
The takeaway
Scammers spin up new sites faster than any blocklist can catch them by hand. The reason the checks above work is that the *operational fingerprint* of a scam — fresh domain, no OV cert, irreversible payments, withdrawal paywall, fake testimonials — is essentially fixed, even when the brand name changes weekly. Learn the fingerprint and you'll catch the next scam before it has a name.
Or skip the manual work and paste the URL into Safe Scanner. It runs every check on this page automatically and returns a verdict before you finish typing your card number.
---
*Originally published at https://gacs.app/blog/how-to-check-if-a-website-is-a-scam. Free website scanner: https://gacs.app/safe-scanner.*
